TestShib.org: Issue with some URLs specified in the metadata.
Kevin Foote
kpfoote at uoregon.edu
Thu Oct 22 12:42:36 EDT 2015
> On Oct 22, 2015, at 9:30 AM, Corey Puffalt <cplists at gmail.com> wrote:
>
> which helped me understand why a separate self-signed certificate is being used for the back-channel endpoints.
>
> For testing purposes I hacked the metadata and simply changed the endpoints referencing 8443 to 443. Should this work? (I know it's not advisable in a production system, but I'm just trying to validate a basic SP configuration). I'm now seeing errors saying "Inbound message issuer was not authenticated." but I'm not sure if this is because I changed the port or if there's some other issue related to my SP configuration causing the issue.
Cory,
Why are you trying to set up backchannel communication on a newer SP?
You should not be using those endpoints (backchannel) unless you are trying to use SAML1 (on purpose, for some reason) and or doing AttributeResolution.
TestShib is set up to do SAML2 just fine on the front side.. use that.
As for what you are doing with the metadata.. no that will not work the metadata is the source of truth for what is going on at the endpoints you can not just “hack” it
into what you want :)
--------
thanks
kevin.foote
More information about the users
mailing list